πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1251 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7fd179ab-f2ab-4ce3-851f-d6da3f0243c6 MEDIUM 4.9 The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths… wordfence
7e36f3a0-2215-4c1c-99c4-9405ad7b913b
< 3.40.1
MEDIUM 4.9 The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injectio… wordfence
7c1e63df-d326-40bf-a428-fdb11150e8d1
< 1.1.7
MEDIUM 4.9 The Booster Elite for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, but n… wordfence
7a5123a7-8eb4-481e-88fe-6310be37a077
< 3.1
MEDIUM 4.9 The Delete Me plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'plugin_delete_me' shortcode in vers… wordfence
77db423c-af60-4539-8e3d-fde997741617
< 3.39
MEDIUM 4.9 The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versi… wordfence
77c125fd-a954-4523-b415-21bf9e835452
< 2.5.4
MEDIUM 4.9 The CYAN Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.5.3. This m… wordfence
76b1f8d8-ab5f-4ce8-a30b-8e9eb0e127a5
< 2.15.20
MEDIUM 4.9 The Infility Global plugin for WordPress is vulnerable to SQL Injection in versions up to 2.15.20 due to insufficient es… wordfence
7669f1d3-450c-4c17-aa1e-44ddda194727
< 2.5.47
MEDIUM 4.9 The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions… wordfence
7633b5fb-e382-4d72-b23b-ce21f2d207cb
< 8.6
MEDIUM 4.9 The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to SQL Injection in version… wordfence
754deb8f-6118-4a35-9059-7a83ec8bfc81 MEDIUM 4.9 The STEdb Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.4 due to insuf… wordfence
74506798-a198-4ea8-8628-01ce4df27abe
< 1.2.3
MEDIUM 4.9 The Secure Downloads plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2… wordfence
73f28157-a613-487b-b7bc-da9a956080b8 MEDIUM 4.9 The Bravo Search & Replace plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due… wordfence
732311d9-8155-42e0-90e7-faf4668d91ca
< 2.7.1
MEDIUM 4.9 The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.0 du… wordfence
72fb0557-27ac-40fe-8440-06c89e1133be
< 2.9.1
MEDIUM 4.9 The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Path Traversal in all vers… wordfence
729e8a06-abaa-4468-8a80-1e5c6cbace92
< 2.0.16
MEDIUM 4.9 The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter… wordfence
7277a022-34ae-40ab-b8b5-6e9ab60d52ed MEDIUM 4.9 The WordPress Auction Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7 d… wordfence
718f5cf2-ca83-4981-9123-4360d043a32d
< 2.1.3.7
MEDIUM 4.9 The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'printer_text' parameter in all versions up… wordfence
7130f325-a0c4-479d-ac85-94542bdb5a79
< 0.9.132
MEDIUM 4.9 The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in vers… wordfence
70f04f90-a0b7-46d1-85da-e898a6981fa2
< 1.0.5
MEDIUM 4.9 The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ver… wordfence
70e059d9-3a69-4d6b-97ea-4f7f40199af9 MEDIUM 4.9 The WP Forum Server plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.2 due to … wordfence
708ec511-5635-43fc-b11d-9d98dfc7ed45 MEDIUM 4.9 The Silvasoft boekhouden plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.1 due… wordfence
6fa5a20e-d3e9-4def-be50-89f5310211f7 MEDIUM 4.9 The WOOEXIM plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.0.0 due to insuffici… wordfence
6f8514c9-0e11-4e26-ba0b-1d08a990b56c
< 3.9.8
MEDIUM 4.9 The CHP Ads Block Detector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings reachabl… wordfence
6d643d07-7533-430b-a1d8-8e66a2a2c5e6
< 5.5.4
MEDIUM 4.9 The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in version… wordfence
6d5264a1-dabf-4630-9871-ab6e14817768
< 2.0.0.2
MEDIUM 4.9 The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for Word… wordfence
← Prev 1248 1249 1250 1251 1252 1253 1254 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top